Work together to provide a simple standardized approach to cybersecurity verification and validation.

A 501(c)6 nonprofit, StateRAMP (dba GovRAMP) levels the playing field for private-sector organizations serving the public sector and reduces hassles for public institutions with strict cybersecurity requirements.

Governments Can Procure and Secure More Efficiently and Confidently with GovRAMP

Diverse government standards and significant data sprawl through cloud service providers complicate today’s security environment, leaving governments less secure than ever amidst increasing cyber threats. GovRAMP lets governments trust but verify service provider products, making procurement more efficient and data more secure.

Service Providers Can Improve Security and Simplify Compliance with GovRAMP

Meeting the complex security standards and supplying (and resupplying) documentation required by various government partners can be confusing, time consuming, and costly. GovRAMP offers transferable credentials through standardized cybersecurity verification, allowing providers to verify once and serve many.

Progressing Snapshot Program Updates

Effective January 1, 2026

Beginning January 1, 2026, the GovRAMP Progressing Snapshot Program will introduce new requirements to ensure every product on the Progressing Product List is actively advancing toward a verified status.

Learn, Connect, and Engage

December 3 at 2:30 pm - 3:00 pm

GovRAMP PMO Office Hours

Please join GovRAMP staff on the first Wednesday of every month from 2:30 pm – 3:00 pm Eastern for Office Hours! This is an open forum for Service Providers, 3PAOs, State and local governments, and higher education institutions.

Join the GovRAMP Program Management Office (PMO) for a live virtual session designed as an open forum to support your questions and engagement. Whether you are navigating the authorization process, preparing for assessments, or seeking clarity on GovRAMP requirements, this 30-minute session is an opportunity to connect directly with GovRAMP staff.

What to Expect:

  • Open Q&A format
  • No formal presentation
  • Opportunity to engage with PMO team members live
  • Questions may be submitted in advance

Submit Your Questions Ahead of Time: govramp.org/office-hours-questions

Join the Event: Click here to join the Microsoft Teams Meeting

December 11 at 11:00 am - 12:00 pm

Q4 GovRAMP Private Sector Member Meeting

This gathering serves as a crucial platform for providers to voice insights, address pertinent issues, and contribute to the evolution of the GovRAMP framework.

We cordially invite GovRAMP private sector members to convene for our quarterly meeting on December 11, 2025, from 11am-12pm EST. This gathering serves as a crucial platform for providers to voice insights, address pertinent issues, and contribute to the evolution of the GovRAMP framework. Expect an email one week prior for further details and engagement instructions.

December 12 at 1:00 pm - 2:00 pm

Q4 GovRAMP Public Sector Member Meeting

This gathering serves as a crucial platform for public sector members to voice insights, address pertinent issues, and contribute to the evolution of the GovRAMP framework.

We cordially invite GovRAMP public sector members ONLY to convene for our quarterly meeting on December 12, 2025, from 1-2pm ET. This gathering serves as a crucial platform for public sector members to voice insights, address pertinent issues, and contribute to the evolution of the GovRAMP framework.

Rev. 5 Updates – StateRAMP Office Hours

StateRAMP staff discusses the NIST 800-53 Rev 5 updates. This special Office Hours was an open forum for Service Providers, 3PAOs, State and local governments, and higher education institutions to ask questions to StateRAMP staff.

Rev. 5 Updates – StateRAMP Office Hours

This panel discussion explores the landscape of cybersecurity and third-party risk management.

Understanding StateRAMP’s Rev 5 Baseline Controls

Explore the latest updates to the StateRAMP Baseline Controls, incorporating NIST 800-53 Rev. 5. Learn how StateRAMP will align with the most current and comprehensive security guidelines for cloud cybersecurity.

Who We Are

As a 501(c)6 nonprofit, our mission is to promote cybersecurity best practices through education and policy development and improve the cyber posture of public institutions and the citizens they serve. We support the shared interests of state and local government entities, their prospective cloud service provider partners, and accredited third-party assessment organizations (3PAOs).